VYPR
Unrated severityNVD Advisory· Published May 14, 2019· Updated Aug 4, 2024

CVE-2019-6576

CVE-2019-6576

Description

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F (All versions < V15.1 Update 1), SIMATIC WinCC Runtime Advanced (All versions < V15.1 Update 1), SIMATIC WinCC Runtime Professional (All versions < V15.1 Update 1), SIMATIC WinCC (TIA Portal) (All versions < V15.1 Update 1), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) (All versions). An attacker with network access to affected devices could potentially obtain a TLS session key. If the attacker is able to observe TLS traffic between a legitimate user and the device, then the attacker could decrypt the TLS traffic. The security vulnerability could be exploited by an attacker who has network access to the web interface of the device and who is able to observe TLS traffic between legitimate users and the web interface of the affected device. The vulnerability could impact the confidentiality of the communication between the affected device and a legitimate user. At the time of advisory publication no public exploitation of the security vulnerability was known.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TLS session key exposure in Siemens SIMATIC HMI panels and WinCC (TIA Portal) allows network attackers to decrypt TLS traffic.

Vulnerability

The vulnerability (CWE-522: Insufficiently Protected Credentials) resides in the TLS implementation of Siemens SIMATIC HMI Comfort Panels 4"–22", Comfort Outdoor Panels 7" & 15", KTP Mobile Panels (KTP400F, KTP700, KTP700F, KTP900, KTP900F), WinCC Runtime Advanced, WinCC Runtime Professional, WinCC (TIA Portal), and HMI Classic Devices (TP/MP/OP/MP Mobile Panel). All versions prior to V15.1 Update 1 are affected, except for Classic Devices where all versions are vulnerable [1]. An attacker with network access to the device's web interface can obtain a TLS session key, which is insufficiently protected.

Exploitation

An attacker must have network access to the web interface of an affected device and be able to observe TLS traffic between a legitimate user and that interface. No authentication is required, but the attack complexity is high (CVSSv3 vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). The attacker first obtains the TLS session key, then uses it to decrypt the observed TLS traffic [1].

Impact

Successful exploitation compromises the confidentiality of communications between the device and a legitimate user. The attacker can decrypt all TLS-encrypted data exchanged during the session, potentially exposing sensitive information such as credentials or process data. The CVSSv3 base score is 5.9, with a high impact on confidentiality [1].

Mitigation

Siemens has released version V15.1 Update 1 which fixes the vulnerability for all affected products except the HMI Classic Devices, for which no fix is available as they are end-of-life. Users should update to V15.1 Update 1 or later. At the time of advisory publication (2019-05-14), no public exploitation was known [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

10
  • Range: < V15.1 Update 1
  • Range: < V15.1 Update 1
  • Range: < V15.1 Update 1
  • Siemens AG/SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel)v5
    Range: All versions
  • Siemens AG/SIMATIC HMI Comfort Outdoor Panels 7" & 15"v5
    Range: All versions < V15.1 Update 1
  • Siemens AG/SIMATIC HMI Comfort Panels 4" - 22"v5
    Range: All versions < V15.1 Update 1
  • Siemens AG/SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900Fv5
    Range: All versions < V15.1 Update 1
  • Siemens AG/SIMATIC WinCC Runtime Advancedv5
    Range: All versions < V15.1 Update 1
  • Siemens AG/SIMATIC WinCC Runtime Professionalv5
    Range: All versions < V15.1 Update 1
  • Siemens AG/SIMATIC WinCC (TIA Portal)v5
    Range: All versions < V15.1 Update 1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.